Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

131–140 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#131

The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

There’s no liability or exposure for recording non-consensually. It’s a public space. There’s not even an edge case. If a random member if the public could walk into the drive-thru (which they can) then anything can be recorded without notification or consent. Edit: Another commenter has made me aware that some states do ban non-consensual audio recordings in public: https://www.dmlp.org/legal-guide/massachusetts-rec…

A restaurant drive thru is private property open to the public. I think there may be a legal difference there.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#132
post #127

It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.

How do we know this was because of a DMCA complaint?

Edit: Never mind -- > https://infosec.exchange/@bobdahacker/115158347003096276

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#133
The blog post got taken down in response to a bullshit DMCA claim filed by a YC-funded company called Cyble

DMCA screenshot https://infosec.exchange/@bobdahacker/115158347003096276

Cyble announcement of YC funding in 2025 https://cyble.com/press/cyble-recognized-among-ai-startups-f...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#134
post #127

It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.

Usually yes, it would go to your ISP. And depending on the ISP they’ll forward it to you or not. This was way more prevalent in the era where movie studios were hiring firms to send bulk DMCAs to people downloading torrents.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#135

Earlier quoted context omitted.

Do you need 2 party consent for recording in a public space?

That's what I'm getting at with the expectation of privacy part. Talking into a drive thru speaker isn't really a private activity since everyone around can kinda hear it, but it'd probably be better to disclaim it anyway since someone attempting to file on you for it still costs money.

Strolling down the sidewalk at a park with a friend and chatting with them isn't necessarily a private activity either: We're in a very public space. Anyone within earshot can hear whatever we're talking about. If the sounds of our conversation winds up being incidentally in the background of someone filming the squirrels the tree frogs or something, then there's probably nothing to be done about that.

But (in some states), it seems that it would be a very different can of worms if I were to elect to deliberately record the conversation I have with my friend without their consent. Even in a public space, that would appear to run directly afoul of the applicable laws.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#136

Earlier quoted context omitted.

in which jurisdiction? Just because there's a device that breaks the law doesn't make the law go away.

Katz v. United States (1967) Glik v. Cunniffe (1st Cir. 2011)

I don't see how either of those cases apply to regular people making recordings of regular citizens (in public, or not) using a microphone.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#137
post #136

Earlier quoted context omitted.

Katz v. United States (1967) Glik v. Cunniffe (1st Cir. 2011)

I don't see how either of those cases apply to regular people making recordings of regular citizens (in public, or not) using a microphone.

I was referring to video with a camera which has a microphone

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#138
40-some years ago in L.A. some guys discovered that a Burger King drive-up kiosk was tied to the restaurant with an RF link. It was a simple matter to determine the frequency and modulation mode and program a hand-held transceiver to use the same link. They set up in an adjacent parking lot with a video camera and set about pranking the customers that drove up. The resulting video, titled "Attack on a Burger King" (these guys were video engineers,) was copied all around town by the same studio rats that shared session outtakes, Red's Tube Bar, etc. It ends with an employee coming out, jogging toward the kiosk, while the hackers convince the customer to flee the angry man approaching them. Dunno if it ever made it to streaming.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#139

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276

The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse.

This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#140

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

Someone should see if YC will fund an ai-first company to help individuals and companies fight back against DMCA abuse and seek compensation
Post reply on HN